Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request.
http://www.securityfocus.com/bid/4091
http://sourceforge.net/project/shownotes.php?release_id=79237